runner

package
v0.2.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: GPL-3.0 Imports: 11 Imported by: 0

Documentation

Overview

Package runner starts pnpm and Trivy as subprocesses: it writes their input files, runs the binary, and gives the caller the combined output.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Credential

type Credential struct {
	UID uint32
	GID uint32
}

Credential identifies the uid and gid a child process runs as. A nil Credential leaves the child under the caller's own identity, the case outside the container.

type Pnpm

type Pnpm interface {
	Resolve(ctx context.Context, in ResolveInput) (ResolveResult, error)
}

Pnpm resolves a package.json into a pnpm-lock.yaml without installing anything, so a resolution only pays for registry metadata.

type PnpmCLI

type PnpmCLI struct {
	// contains filtered or unexported fields
}

PnpmCLI resolves dependencies by running the pnpm CLI through Node.js, the packaging pnpm ships.

func NewPnpmCLI

func NewPnpmCLI(bin, cacheDir string, asUser *Credential) *PnpmCLI

NewPnpmCLI builds a PnpmCLI. bin is the path to pnpm's own entry point, <pnpm dir>/package/bin/pnpm.cjs, run through node. cacheDir holds pnpm's content store and registry metadata cache. asUser is nil outside the container.

func (*PnpmCLI) Resolve

func (c *PnpmCLI) Resolve(ctx context.Context, in ResolveInput) (ResolveResult, error)

Resolve writes the manifest and a pnpm-workspace.yaml pinned to in.Target, runs "pnpm install --lockfile-only" and reads the resulting lockfile back. The store and cache sit under cacheDir, so resolutions share downloaded metadata across calls.

type ResolveInput

type ResolveInput struct {
	Dir      string
	Manifest []byte
	Target   store.Target
}

ResolveInput is a resolution request. Dir is a temporary directory the caller owns; Resolve writes the manifest and workspace file into it and reads pnpm-lock.yaml back from it.

type ResolveResult

type ResolveResult struct {
	Lockfile []byte // pnpm-lock.yaml
	Output   string // combined stdout and stderr, shown to the user on failure
}

ResolveResult is the outcome of a resolution.

type Trivy

type Trivy interface {
	// ScanSBOM scans the CycloneDX document at sbomPath and writes a JSON
	// report to outPath. It returns the combined output.
	ScanSBOM(ctx context.Context, sbomPath, outPath string) (string, error)
	// ConvertToCycloneDX converts the JSON report at reportPath into a
	// CycloneDX document at outPath. It returns the combined output.
	ConvertToCycloneDX(ctx context.Context, reportPath, outPath string) (string, error)
	// UpdateDB downloads the vulnerability database. It returns the
	// combined output.
	UpdateDB(ctx context.Context) (string, error)
}

Trivy scans a CycloneDX document for known vulnerabilities, converts a scan report to CycloneDX, and refreshes the vulnerability database.

type TrivyCLI

type TrivyCLI struct {
	// contains filtered or unexported fields
}

TrivyCLI runs the trivy binary.

func NewTrivyCLI

func NewTrivyCLI(bin, cacheDir string, asUser *Credential) *TrivyCLI

NewTrivyCLI builds a TrivyCLI that runs bin with its vulnerability database cache under cacheDir. asUser is nil outside the container.

func (*TrivyCLI) ConvertToCycloneDX

func (c *TrivyCLI) ConvertToCycloneDX(ctx context.Context, reportPath, outPath string) (string, error)

ConvertToCycloneDX converts the JSON report at reportPath into a CycloneDX document at outPath. convert reads an existing report and touches no database, but --cache-dir is a global trivy flag that defaults to a path under HOME regardless of the subcommand; passing it explicitly, as ScanSBOM already does, keeps this from depending on HOME being set to something the caller can write.

func (*TrivyCLI) ScanSBOM

func (c *TrivyCLI) ScanSBOM(ctx context.Context, sbomPath, outPath string) (string, error)

ScanSBOM scans the CycloneDX document at sbomPath and writes a JSON report to outPath. It skips a database download: the caller refreshes the database once per job, not once per scan.

func (*TrivyCLI) UpdateDB

func (c *TrivyCLI) UpdateDB(ctx context.Context) (string, error)

UpdateDB downloads the vulnerability database only, without scanning anything.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL